Data Mapping & Records of Processing Activities (RoPA)
What is Data Mapping?
Visual or documented representation of:
- Where personal data enters your system
- Which systems process it
- Where it's stored
- Who has access
- Where it exits (shared with third parties)
- When it's deleted
What is RoPA?
Detailed inventory of every processing activity:
- What data is processed
- Why (purpose)
- For how long (retention)
- Who accesses it
- Security measures
Step 1: Identify All Data Sources
- Customer-facing forms (website, app)
- Internal systems (HR, CRM, ERP)
- Third-party integrations (APIs, webhooks)
- Analytics & tracking
- Email & communication systems
- Backup systems
Step 2: Document Data Types
For each source:
- Data category (name, email, phone, payment, location, behavior)
- Data sensitivity (basic personal, sensitive, financial)
- Volume
- Frequency
Step 3: Map Processing Activities
For each data type:
- Purpose of collection
- Legal basis (typically consent)
- Retention period
- Recipient (who accesses)
- Storage location
- Encryption method
- Backup location
Step 4: Identify Vendors & Sub-processors
- Cloud providers
- Email vendors
- Analytics platforms
- CRM systems
- Payment processors
- Backup services
Tools
- Spreadsheet-based (Excel/Google Sheets)
- Specialized software (Nymity, OneTrust)
- Custom database for large volumes
Disclaimer: General informational article. Consult compliance experts. what is dpdp act 2023
Get Compliant: Start your free DPDP compliance assessment dpdp penalties explained dpdp vs gdpr DPDP Compliance Hub